Difficulty
N/A
Published Date
August 7, 2026
Summary
Collection of Sherlock writeups inside the HTB CDSA Preparation path
Tags
HTBDefensiveCollections
The HTB CDSA Preparation path contains a collection of Sherlocks to practice the skills that are required to pass the CDSA certification. These skills mainly revolve around DFIR, focusing on endpoint forensics and memory forensics. In this page, you will find a collection of the writeups I have written for each of these Sherlocks. As I progressed through these Sherlocks, I got better at digital forensics and my methodology got better with time. This progress can be seen as I completed each Sherlock, and it is reflected in my writing.
Sherlock Name | Summary | Link |
Unit42 (Very Easy) | “In this very easy Sherlock, you will familiarize yourself with Sysmon logs and various useful EventIDs for identifying and analyzing malicious activities on a Windows system.” | |
Campfire-1 (Very Easy) | “In this Very Easy Sherlock, players will go through artefacts and logs from the Domain controller as well as endpoint artefacts from where Kerberoast attack activity was sourced” | |
Recollection (Easy) | “Recollection is an easy difficulty Sherlock where you are tasked with carrying out analysis of a memory dump to understand the actions of an attacker and what else within the environment may have been affected.” | |
RogueOne (Easy) | “In this scenario, the Security Information and Event Management (SIEM) system at Forela has detected a series of alerts in a brief period, signaling potential Command and Control (C2) communication originating from an employee, Simon Stark's, workstation.” | |
LogJammer (Easy) | “The consultancy Forela-Security would like to gauge your knowledge of Windows Event Log Analysis.” | |
Trojan (Easy) | “You will be given a set of artefacts relating to a workstation that has been compromised by a malware Trojan. You need to analyse the different pieces of evidence to extract IOCs and reconstruct the phases of the infection.” | |
Tracer (Easy) | “A junior SOC analyst on duty has reported multiple alerts indicating the presence of PsExec on a workstation. ” | |
ReliableThreat (Medium) | “In this Sherlock, you must analyze the tools used by a developer and understand how they may have been the victim of a security breach.” | |
Jinkies (Medium) | “Jinkies is a medium difficulty Sherlock where you'll investigate the theft of intellectual property from an organisation called Cloud-guru. Find the source of the leak and answer the questions for senior management!” | |
Detroit Becomes Human (Hard) | “Alonzo Spire is fascinated by AI after noticing the recent uptick in usage of AI tools to help aid in daily tasks. […] Without any second thought, he downloaded [an AI] tool. […] A DFIR analyst was notified of a possible incident on Forela's sysadmin machine. You are tasked to help the analyst in analysis to find the true source of this odd incident.” | |
Streamer (Hard) | “In this Sherlock, Players will investigate an incident inspired by rise of malicious google ads for softwares mostly used by individuals like streaming, productivity or note taking applications. Players will analyze windows artifacts to uncover all stages of cyber kill chain.” |